Junglewise Threat Intelligence

CVE-2026-93108: Linux kernel RDMA/ipoib use-after-free in module teardown

CVE-2026-93108 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's RDMA/IPoIB module has a defect in its shutdown sequence where unload operations can proceed before pending RCU callbacks finish executing, leading to code execution in already-unloaded memory. This can cause kernel crashes or memory corruption when the IPoIB module is unloaded while network operations are in flight.

Technical details

The vulnerability is a use-after-free (or more precisely, a use-after-unload) in the RDMA/ipoib kernel module's teardown path. IPoIB reclamation completions are signaled from within RCU callbacks; however, the module teardown does not wait for these callbacks to drain before destroying the workqueue and unloading the module. This means RCU callbacks can execute code after the module code segment has been unmapped from memory. The fix adds calls to rcu_barrier() in both the module initialization error path and the module cleanup path to ensure all queued RCU callbacks complete before proceeding with unload. Client registration failures that queue callbacks are also covered by waiting after workqueue teardown.

Affected products

  • Linux Linux kernel multiple versions across 2.6.11 through 7.2 as indicated by stable tree branches

Timeline

  • 2026-09-17: disclosed
  • 2026-07-12: patched: Fix authored; stable releases applied from 2026-09-14 onwards

References

Related threats